New issue
Advanced search Search tips

Issue 676907 link

Starred by 2 users

Issue metadata

Status: WontFix
Owner: ----
Closed: Dec 2016
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Linux
Pri: 2
Type: Bug



Sign in to add a comment

Integer-overflow in blink::operator-

Project Member Reported by ClusterFuzz, Dec 24 2016

Issue description

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=6379363769778176

Fuzzer: inferno_twister
Job Type: linux_ubsan_chrome
Platform Id: linux

Crash Type: Integer-overflow
Crash Address: 
Crash State:
  blink::operator-
  blink::FrameView::contentsToFrame
  blink::FrameView::contentsToFrame
  
Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_ubsan_chrome&range=418843:418863

Minimized Testcase (3.55 Kb): https://cluster-fuzz.appspot.com/download/AMIfv944ZZmVcfBa4Lb06ujme1pBRVXhOUVhXDtG3PxX5iwhofO93Ys8818dVAytpONdzqq2Y2OqAJSDV8c13C1ylyQ-YN1-qqYlwmTPfdf5hGdGgtwa0TU0s0W6mqx75eWS_wL5zyn2TDww1UIUzfHqOYhaLRDysQ?testcase_id=6379363769778176

Issue filed automatically.

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
 
Cc: wangxianzhu@chromium.org skyos...@chromium.org dcheng@chromium.org
Components: Blink>HTML>Frame
Labels: Test-Predator-Wrong M-57
Find it and regression range not provided any possible suspects. through code search on file FrameView.cpp, cc-ing few developers who worked on this file. could any one please take a look?

Status: WontFix (was: Untriaged)
This is not a regression. Blink code never checks for integer overflow in layout code though we do have saturated arithmetic for LayoutUnits. This has no security issues.

Sign in to add a comment